Re: Retiring lpr and lpd
Tomoaki AOKI <[email protected]> Sat, 21 Feb 2026 08:40:52 +0900
| Newsgroups | gmane.os.freebsd.architechture |
|---|---|
| Organization | Junchoon corps |
| Message-ID | <[email protected]> |
On Fri, 20 Feb 2026 22:56:25 +0100 Dag-Erling Smørgrav <[email protected]> wrote: > Steve Kargl <[email protected]> writes: > > Did you miss the "What is the problem? Don't fix what isn't broken." > > No, I didn't miss it. But Slawa and you clearly missed me telling you > _twice_ that it _is_ broken. > > > Is there an open CVE that we need to worry about? > > There are known bugs, for which I have patches. It is currently unclear > whether a CVE will be assigned. While preparing those patches, I > learned that lpd is _an absolute shitshow_. It runs with elevated > privileges, accepts input from the network without authentication, and > does next to no input validation or bounds checking. It needs to be > overhauled, replaced, or removed, and this is me giving you _one and a > half years' notice_ to do either of the former before I do the latter. > > DES > -- > Dag-Erling Smørgrav - [email protected] Are there any alternatives that can be incorporated into base, including dependencies mandatory to work, and maintained? print/cups seems to depend on GPL'ed matters by default and I'm not sure if it still "actually" works at least the level of lpr families when all GPL'ed options disabled. And sysutils/LPRng seems to be GPL'ed and having no maintainer. Regards. -- Tomoaki AOKI <[email protected]>